XSS Vulnerability in PrestaShop 1.7.6.2 QuickAccess Link Addition/Removal

XSS Vulnerability in PrestaShop 1.7.6.2 QuickAccess Link Addition/Removal

CVE-2020-6632 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In PrestaShop 1.7.6.2, XSS can occur during addition or removal of a QuickAccess link. This is related to AdminQuickAccessesController.php, themes/default/template/header.tpl, and themes/new-theme/js/header.js.

Learn more about our Web Application Penetration Testing UK.